First published: Fri Mar 22 2013(Updated: )
The v1 API in OpenStack Glance Essex (2012.1), Folsom (2012.2), and Grizzly, when using the single-tenant Swift or S3 store, reports the location field, which allows remote authenticated users to obtain the operator's backend credentials via a request for a cached image.
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
OpenStack Glance | =v1 | |
OpenStack Essex | =2012.1 | |
OpenStack Folsom | =2012.2 | |
Amazon S3 Store | ||
OpenStack Swift | ||
pip/glance | <11.0.0a0 | 11.0.0a0 |
All of | ||
OpenStack Glance | =v1 | |
Any of | ||
OpenStack Essex | =2012.1 | |
OpenStack Folsom | =2012.2 | |
Any of | ||
Amazon S3 Store | ||
OpenStack Swift |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.